Back

MEDIUM

ftrace: Fix null pointer dereference in ftrace_add_mod()

Published May 1, 2025

Description

The @ftrace_mod is allocated by kzalloc(), so both the members {prev,next} of @ftrace_mode->list are NULL, it's not a valid state to call list_del(). If kstrdup() for @ftrace_mod->{func|module} fails, it goes to @out_free tag and calls free_ftrace_mod() to destroy @ftrace_mod, then list_del() will write prev->next and next->prev, where null pointer dereference happens.

BUG: kernel NULL pointer dereference, address: 0000000000000008 Oops: 0002 [#1] PREEMPT SMP NOPTI Call Trace: <TASK> ftrace_mod_callback+0x20d/0x220 ? do_filp_open+0xd9/0x140 ftrace_process_regex.isra.51+0xbf/0x130 ftrace_regex_write.isra.52.part.53+0x6e/0x90 vfs_write+0xee/0x3a0 ? __audit_filter_op+0xb1/0x100 ? auditd_test_task+0x38/0x50 ksys_write+0xa5/0xe0 do_syscall_64+0x3a/0x90 entry_SYSCALL_64_after_hwframe+0x63/0xcd Kernel panic - not syncing: Fatal exception

So call INIT_LIST_HEAD() to initialize the list member to fix this issue.

Affected products

Remediation

Red Hat statement

The patch fixes a kernel NULL pointer dereference in the ftrace_add_mod() function. When memory allocation (kzalloc()) succeeds but subsequent kstrdup() fails, the error path calls list_del() on an uninitialized list head (ftrace_mod->list). This leads to a kernel panic due to prev->next or next->prev being NULL. This bug can be triggered by local privileged users (typically those interacting with Ftrace via debugfs or similar kernel tracing interfaces).

Metrics

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published May 1, 2025
Updated May 11, 2026
Reserved May 1, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date May 1, 2025